CVE-2026-34005: OS Command Injection
In Sofia on Xiongmai DVR/NVR (AHB7008T-MH-V2 and NBD7024H-P) 4.03.R11 devices, root OS command injection can occur via shell metacharacters in the HostName value via an authenticated DVRIP protocol (TCP port 34567) request to the NetWork.NetCommon configuration handler, because system() is used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34005?
The severity of CVE-2026-34005 is classified as high due to the potential for root OS command injection.
How can I fix CVE-2026-34005?
To fix CVE-2026-34005, users should upgrade Xiongmai Sofia devices to a version that eliminates the command injection vulnerability.
Who is affected by CVE-2026-34005?
The devices affected by CVE-2026-34005 include Xiongmai Sofia (AHB7008T-MH-V2) and Xiongmai Sofia (NBD7024H-P) running version 4.03.R11.
What type of vulnerability is CVE-2026-34005?
CVE-2026-34005 is classified as an OS command injection vulnerability due to improper handling of user input in the HostName value.
Is authentication required to exploit CVE-2026-34005?
Yes, an authenticated request via the DVRIP protocol is required to exploit CVE-2026-34005.